capability

Analytics Rules

Microsoft Sentinel analytics rules detect threats by running scheduled or near-real-time logic against workspace data and creating alerts and incidents.

capabilitiesCurrent

Relationships

Configuration Methods

MethodSupportReference or Gap
PortalSupported Reference
PowerShellGapNo product-specific PowerShell automation surface is recorded for this capability yet.
REST APISupported Reference
GraphGapNo supported Microsoft Graph configuration surface is recorded for this capability yet.
ARMSupported Reference
BicepSupported Reference
TerraformSupportedazurermazurerm_sentinel_alert_rule_scheduled Reference

Fusion, ML behavior analytics, and some NRT rule kinds are not covered by azurerm; use azapi_resource against Microsoft.SecurityInsights/alertRules for those kinds.

GitHub ActionsSupported Reference
Azure DevOpsSupported Reference